<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Safelight Security Advisors &#187; In the News</title>
	<atom:link href="http://safelightsecurity.com/news/category/in-the-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://safelightsecurity.com</link>
	<description>Enabling organizations to proactively manage information security risks</description>
	<lastBuildDate>Thu, 26 Aug 2010 16:46:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Threatpost: Rob Cheyne on Security Education and the Problem of People in Security</title>
		<link>http://safelightsecurity.com/news/2010/07/08/threatpost-rob-cheyne-on-security-education-and-the-problem-of-people-in-security/</link>
		<comments>http://safelightsecurity.com/news/2010/07/08/threatpost-rob-cheyne-on-security-education-and-the-problem-of-people-in-security/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 16:25:59 +0000</pubDate>
		<dc:creator>Jess Hawks</dc:creator>
				<category><![CDATA[In the News]]></category>

		<guid isPermaLink="false">http://safelightsecurity.com/?p=742</guid>
		<description><![CDATA[Safelight CEO Rob Cheyne talks with Threatpost&#8217;s Dennis Fisher about why security is every employee&#8217;s responsibility and how companies can shift the way they communicate with users about the value of information and their role in protecting it. 

Listen to the podcast.





 
 ]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="0in 0in 0pt;"><span style="Times New Roman;">Safelight CEO Rob Cheyne talks with Threatpost&#8217;s Dennis Fisher about why security is every employee&#8217;s responsibility and how companies can shift the way they communicate with users about the value of information and their role in protecting it. <span style="yes;"></span></p>

<p class="MsoNormal" style="0in 0in 0pt;"><a href="http://threatpost.com/en_us/blogs/rob-cheyne-security-education-and-problem-people-security-070810"><span style="Times New Roman;">Listen to the podcast.</span></a></p>

<p class="MsoNormal" style="0in 0in 0pt;"></p>
<p class="MsoNormal" style="0in 0in 0pt;"></p>
<p class="MsoNormal" style="0in 0in 0pt;"></p>

<div><span style="Times New Roman;"> </span></div>
<span style="Times New Roman;"> </span>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/07/08/threatpost-rob-cheyne-on-security-education-and-the-problem-of-people-in-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TechNewsWorld:  Rob Cheyne on Ridding the Web of the XSS Scourge</title>
		<link>http://safelightsecurity.com/news/2009/10/30/technewsworld-rob-cheyne-on-ridding-the-web-of-the-xss-scourge/</link>
		<comments>http://safelightsecurity.com/news/2009/10/30/technewsworld-rob-cheyne-on-ridding-the-web-of-the-xss-scourge/#comments</comments>
		<pubDate>Fri, 30 Oct 2009 15:16:24 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[In the News]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=60</guid>
		<description><![CDATA[While many developers have heard of the common attacks such as SQL injection and cross-site scripting, most have not actually seen the attacks fully exploited.  “Until people see the repercussions they are not inclined to go back into their code and clean up the issues, which leads to the state we’re in today,” said Rob [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="0in 0in 0pt;"><span style="Times New Roman;">While many developers have heard of the common attacks such as SQL injection and cross-site scripting, most have not actually seen the attacks fully exploited.<span style="yes;">  </span>“Until people see the repercussions they are not inclined to go back into their code and clean up the issues, which leads to the state we’re in today,” said Rob Cheyne, CEO, Safelight Security Advisors. </span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span style="Times New Roman;">The application security classes Rob teaches and Safelight’s online learning courses feature training that shows developers what they’re really up against when it comes to these types of attacks.</span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span style="Times New Roman;">View Safelight’s cross-site scripting and SQL injections demonstrations on YouTube </span><a href="http://www.youtube.com/user/securityadvisors"><span style="Times New Roman;">here</span></a><span style="Times New Roman;">.</span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><a href="http://www.technewsworld.com/rsstory/68410.html"><span style="Times New Roman;">Full Story</span></a></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span style="Times New Roman;"> </span></p>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2009/10/30/technewsworld-rob-cheyne-on-ridding-the-web-of-the-xss-scourge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CSTechCast: Rob Cheyne on Why Secure Code is Lacking</title>
		<link>http://safelightsecurity.com/news/2009/09/21/cstechcast-rob-cheyne-on-why-secure-code-is-lacking/</link>
		<comments>http://safelightsecurity.com/news/2009/09/21/cstechcast-rob-cheyne-on-why-secure-code-is-lacking/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 18:43:55 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[In the News]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=58</guid>
		<description><![CDATA[Rob Cheyne talks to CSTechCast about why secure code is lacking, and what can be done about it.  What are some of the common mistakes developers make, the biggest security misconceptions and how best to balance business and IT security requirements? Listen to the podcast.
 ]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="0in 0in 0pt;"><span style="Times New Roman;">Rob Cheyne talks to </span><a href="http://cstechcast.com/"><span style="Times New Roman;">CSTechCast</span></a><span style="Times New Roman;"> about why secure code is lacking, and what can be done about it.<span style="yes;">  </span>What are some of the common mistakes developers make, the biggest security misconceptions and how best to balance business and IT security requirements? Listen to the</span><a href="http://www.cstechcast.com/home.aspx?Episode=89"><span style="Times New Roman;"> podcast</span></a><span style="Times New Roman;">.</span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span style="Times New Roman;"> </span></p>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2009/09/21/cstechcast-rob-cheyne-on-why-secure-code-is-lacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IT World: Rob Cheyne on Developer Tools and Why You Don’t Use Them</title>
		<link>http://safelightsecurity.com/news/2009/08/13/it-world-rob-cheyne-on-developer-tools-and-why-you-don%e2%80%99t-use-them/</link>
		<comments>http://safelightsecurity.com/news/2009/08/13/it-world-rob-cheyne-on-developer-tools-and-why-you-don%e2%80%99t-use-them/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 20:31:35 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[In the News]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=56</guid>
		<description><![CDATA[Some of the reasons developers don’t use tools: Not needing the functionality, they’re not part of the development process, and it’s hard to convince management they’re necessary.  Rob Cheyne, founder and CEO, Safelight Security Advisors, weighs in on these issues and points to debuggers as an example of a tool category that took some [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="0in 0in 0pt;"><span style="Times New Roman;">Some of the reasons developers don’t use tools: Not needing the functionality, they’re not part of the development process, and it’s hard to convince management they’re necessary. <span style="yes;"> </span>Rob Cheyne, founder and CEO, Safelight Security Advisors, weighs in on these issues and points to debuggers as an example of a tool category that took some time to catch on. <span style="yes;"> </span>“The tools that truly improve ROI will always be adopted in the long run,” says Cheyne.</span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><a href="http://www.itworld.com/development/74088/developer-tools-you-dont-use-and-why-you-dont-use-them"><span style="Times New Roman;">Full Story</span></a></p>
Rob is an expert in training development teams on application security and can be contacted at rcheyne@securityadvisors.com
<p class="MsoNormal" style="0in 0in 0pt;"></p>
<p class="MsoNormal" style="0in 0in 0pt;"></p>
<p class="MsoNormal" style="0in 0in 0pt;"></p>

<div><span style="Times New Roman;"> </span></div>
<span style="Times New Roman;"> </span>
<p class="MsoNormal" style="0in 0in 0pt;"></p>
<p class="MsoNormal" style="0in 0in 0pt;"></p>
<p class="MsoNormal" style="0in 0in 0pt;"></p>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2009/08/13/it-world-rob-cheyne-on-developer-tools-and-why-you-don%e2%80%99t-use-them/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Human Factor in the Twitter Hack</title>
		<link>http://safelightsecurity.com/news/2009/07/24/the-human-factor-in-the-twitter-hack/</link>
		<comments>http://safelightsecurity.com/news/2009/07/24/the-human-factor-in-the-twitter-hack/#comments</comments>
		<pubDate>Fri, 24 Jul 2009 21:16:01 +0000</pubDate>
		<dc:creator>Rob</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[In the News]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=55</guid>
		<description><![CDATA[An interesting little rumor recently made its way across the Internet.  Twitter, the poster child for Web 2.0 social networking, has apparently been having some security problems. It turns out that the attackers didn&#8217;t need to do anything sophisticated at all.  For at least one of their systems, Twitter&#8217;s admin password was, wait [...]]]></description>
			<content:encoded><![CDATA[<p>An interesting little rumor recently made its way across the Internet.  Twitter, the poster child for Web 2.0 social networking, has apparently been having some security problems. It turns out that the attackers didn&#8217;t need to do anything sophisticated at all.  For at least one of their systems, Twitter&#8217;s admin password was, wait for it &#8230; <a href="http://www.techcrunch.com/2009/07/15/another-security-tip-for-twitter-dont-use-password-as-your-password/" target="_blank">password</a>.</p>

<p>As an author of a well-known password cracking tool <a href="http://en.wikipedia.org/wiki/L0phtCrack" target="_blank">L0phtCrack</a>, I have seen thousands of cracked passwords at a time, and I&#8217;ve got to tell you, this is not particularly surprising.  I can assure you that the most popular password on the planet is indeed password, followed closely by things like:</p>

<ul>
	<li>secret</li>
	<li>welcome123 (or other default passwords)</li>
	<li>qwerty, asdfg, (and other silly keyboard patterns)</li>
	<li>Porsche, Mercedes, Ferrari, etc.</li>
	<li>Red Sox, Yankees, Patriots, etc., etc., etc.</li>
	<li>Name and/or birth dates of loved ones, friends, pets, etc.</li>
</ul>

<p>You get the idea.  Password technology has been fundamentally flawed for quite some time, but with solid security practices, and the right training, it can still be used effectively if you know how.  Unfortunately, most people don&#8217;t know how, even some of the ones who should.</p>

<p>Of course, Twitter&#8217;s comeback was that this was for a system that didn&#8217;t need to be as secure.  I&#8217;ve got to be honest here.  I&#8217;ve heard that one before – it&#8217;s called an excuse.  We need to stop being afraid to come out and say, &#8220;Yes, there was a security incident.  We were a bit lax in our security procedures and we have addressed the holes.  We&#8217;re taking it seriously and correcting the mistake to lessen the likelihood that it happens again.&#8221;</p>

<p>As long as there are humans running systems, there will always be security flaws.  Everyone makes mistakes, and some of those mistakes cause security holes.</p>

<p>But c&#8217;mon, password???  I&#8217;ve conducted security reviews for many large enterprises, and from what I&#8217;ve seen, when people make such basic mistakes, there are almost certainly far bigger flaws elsewhere in the system.</p>

<p>You see, passwords are just the tip of the iceberg.  Building a secure system requires a very different mindset than simply &#8220;make it work.&#8221;  And it is significantly more difficult if everyone on the team doesn&#8217;t have it.  In my next post, I&#8217;ll talk more about the effects of the human factor in security and some of the biggest people problems.</p>

<p>&#8211;Rob Cheyne<br />
rcheyne@securityadvisors.com</p>
]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2009/07/24/the-human-factor-in-the-twitter-hack/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Safelight Security Advisors Launches e-Learning Security Courses for Software Developers</title>
		<link>http://safelightsecurity.com/news/2009/02/25/safelight-security-advisors-launches-e-learning-security-courses-for-software-developers/</link>
		<comments>http://safelightsecurity.com/news/2009/02/25/safelight-security-advisors-launches-e-learning-security-courses-for-software-developers/#comments</comments>
		<pubDate>Wed, 25 Feb 2009 14:21:17 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[In the News]]></category>
		<category><![CDATA[Press Releases]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=46</guid>
		<description><![CDATA[FOR IMMEDIATE RELEASE

Media Contact:
Kim Novino
Safelight Security Advisors
508-981-9732
knovino@securityadvisors.com

Safelight Security Advisors Launches e-Learning Security Courses for Software Developers

Web-Based Modules Offer Comprehensive, Cost-Effective On-Demand Training

Boston, MA, February 25, 2009 – Safelight Security Advisors, (www.securityadvisors.com), a security education company that delivers application security training to developers worldwide, today introduced electronic learning versions of their widely-taught instructor-led courses: Application Security [...]]]></description>
			<content:encoded><![CDATA[<p>FOR IMMEDIATE RELEASE</p>

<p>Media Contact:<br />
Kim Novino<br />
Safelight Security Advisors<br />
508-981-9732<br />
<a href="mailto:knovino@securityadviosrs.com">knovino@securityadvisors.com</a></p>

<h2><strong>Safelight Security Advisors Launches e-Learning Security Courses for Software Developers</strong></h2>

<h3>Web-Based Modules Offer Comprehensive, Cost-Effective On-Demand Training</h3>

<p><strong>Boston, MA, February 25, 2009</strong> – Safelight Security Advisors, (<a title="Safelight Security Advisors" href="http://securityadvisors.com">www.securityadvisors.com</a>), a security education company that delivers application security training to developers worldwide, today introduced electronic learning versions of their widely-taught instructor-led courses: Application Security Fundamentals and Secure .NET Coding.  The courses bring a real-world understanding of the hacker mindset to application developers in a comprehensive, yet cost-effective computer-based offering that makes it easier for developers to learn at their own pace and schedule.  Users can sign up for a free demo license at <a title="Offers" href="http://securityadvisors.com/offerings/hacker/">www.securityadvisors.com/offerings/hacker/</a>.  A third course, Secure Java Coding, will be available at the end of Q1 2009.</p>

<p>Unlike other security e-learning products which provide basic information delivered in a static format, Safelight’s e-Learning courses incorporate deep content with interactive features designed to engage students. The modules offer Adobe Flash-based web content, clear and logical menu-based navigation that allows students to pause, skip or jump to any part of the course at any time, learning objectives that are reiterated throughout the course, and interactive games and quizzes to increase student interest and re-enforce their learning.</p>

<p>“The truth is that an attacker knows much more about breaking into your system than the average developer knows about writing secure code.  These advanced e-Learning courses shed some light on what developers are really up against and then teaches them what they need to know to build solid defenses,” said Rob Cheyne, founder and CEO, Safelight Security Advisors.  “Our computerized courses combine the depth of our instructor-led training with e-learning best practices designed to utilize the different ways people learn.”</p>

<p>Safelight’s e-Learning courses are currently being rolled out to customers in the retail, government, financial services and employment services sectors.</p>

<p>The Application Security Fundamentals e-learning course can be completed in 3-4 hours and is appropriate for all members of the application development team.  No prior background in security is needed.  The Secure .NET Coding course is for experienced developers and is designed to be used in combination with Application Security Fundamentals.  For more information, visit www.securityadvisors.com.</p>

<h2><strong>About Safelight Security Advisors</strong></h2>

<p>Safelight Security Advisors is an information security education company that delivers application security training programs through effective e-Learning and instructor-led training.  Safelight develops its information security education programs for development teams, executives and general staff.  The company’s core courses focus on application security, secure coding, secure architecture &amp; design, and security awareness. For more information, visit www.securityadvisors.com.</p>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2009/02/25/safelight-security-advisors-launches-e-learning-security-courses-for-software-developers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Paul Hinkle presenting at SD West on March 13th</title>
		<link>http://safelightsecurity.com/news/2009/01/14/paul-hinkle-presenting-at-sd-west-on-march-13th/</link>
		<comments>http://safelightsecurity.com/news/2009/01/14/paul-hinkle-presenting-at-sd-west-on-march-13th/#comments</comments>
		<pubDate>Wed, 14 Jan 2009 18:31:00 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[In the News]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=33</guid>
		<description><![CDATA[Banking on Education: A Case Study on Developer Security Training


Speaker:  Paul  Hinkle (Chief Technology Officer, Safelight Security Advisors)
Date/Time: Friday (March 13, 2009)   1:30pm — 3:00pm
Track: Security
Presentation Format: 90-minute Case Studies
Audience level: All


Presentation Abstract
Four years in the making, State Street Bank has created a pioneering security education program for its internal developers: [...]]]></description>
			<content:encoded><![CDATA[<h2>Banking on Education: A Case Study on Developer Security Training</h2>

<p>
<span class="bodytext"><strong>Speaker: </strong> <a class="bodytext" href="https://www.cmpevents.com/SDw9/a.asp?option=G&amp;V=3&amp;id=628826" rel="nofollow">Paul  Hinkle</a> (Chief Technology Officer, Safelight Security Advisors)</span><br />
<strong>Date/Time: </strong><span class="bodytext">Friday</span> (March 13, 2009)   1:30pm — 3:00pm<br />
<strong>Track: </strong><span class="bodytext">Security</span><br />
<strong>Presentation Format: </strong><span class="bodytext"><em>90-minute </em>Case Studies</span><br />
<strong>Audience level: </strong>All
</p>

<h3>Presentation Abstract</h3>
<p>Four years in the making, State Street Bank has created a pioneering security education program for its internal developers: both employees and contractors located in multiple countries. This case study will discuss how to properly implement an internal security training program. It will discuss the unique challenges State Street faced, how they were addressed, and the process the company went through to create a successful training program that is now mandatory for all staff involved in systems development worldwide.</p>

<p>Please email <a href="mailto:info@securityadvisors.com">info@securityadvisors.com</a> for a discount code to receive $100 off the lowest price.</p>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2009/01/14/paul-hinkle-presenting-at-sd-west-on-march-13th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CSO Magazine: Rob Cheyne Pushes Developer Security Awareness</title>
		<link>http://safelightsecurity.com/news/2008/06/13/cso-magazine-rob-cheyne-pushes-developer-security-awareness/</link>
		<comments>http://safelightsecurity.com/news/2008/06/13/cso-magazine-rob-cheyne-pushes-developer-security-awareness/#comments</comments>
		<pubDate>Fri, 13 Jun 2008 13:23:24 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[In the News]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=18</guid>
		<description><![CDATA[(10 June 2008)

Rob Cheyne, founder and CEO, Safelight Security Advisors, believes that security is everyone&#8217;s job.  The @stake and Symantec veteran says security practices must be woven into application development and everything else.  He spoke with CSO Magazine&#8217;s Kate Walsh about why enterprise wide security education is critical.

Full Story]]></description>
			<content:encoded><![CDATA[<p>(10 June 2008)</p>

<p>Rob Cheyne, founder and CEO, Safelight Security Advisors, believes that security is everyone&#8217;s job.  The @stake and Symantec veteran says security practices must be woven into application development and everything else.  He spoke with CSO Magazine&#8217;s Kate Walsh about why enterprise wide security education is critical.</p>

<p><a href="http://www.csoonline.com/article/377613/Rob_Cheyne_Pushes_Developer_Security_Awareness" target="_blank">Full Story</a></p>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2008/06/13/cso-magazine-rob-cheyne-pushes-developer-security-awareness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
